Does Cyber Essentials require a VPN?
No. Cyber Essentials does not mandate a VPN. Apply the scheme rules to each in-scope remote administration path, boundary firewall, account and cloud service; a VPN is one possible design.

Section 01
Does Cyber Essentials require a VPN?
No - Cyber Essentials does not require a VPN. Under v3.3, check the applicable requirements for in-scope accounts, remote administration and boundary firewalls. A VPN may be useful, but its presence alone does not establish a pass.
Section 02
What v3.3 actually requires for remote access
- Apply MFA to in-scope cloud services and to remote administration where the current scheme criteria require it; check each account and service.
- Restrict and document internet-facing access and remote administration under the firewall and secure-configuration rules.
- Use suitable encrypted transport and stronger authentication where appropriate. TLS 1.2 and phishing-resistant MFA are useful design choices, but not universal stand-alone Cyber Essentials mandates.
See the User Access Control pillar guide for the full detail.
Section 03
Where a VPN is a good solution
- Accessing on-premises servers or file shares from outside the office.
- Presenting a consistent egress IP for allow-listing.
- Protecting traffic on untrusted networks.
- Legacy applications that assume a trusted LAN.
A VPN can be part of a compliant design when the in-scope endpoints, accounts, firewalls and services also meet their applicable requirements.
Section 04
Where a VPN is not needed
Cloud-first organisations that access all corporate services through Microsoft 365, Google Workspace, or SaaS tools - with identity-provider MFA enforced via Conditional Access - may meet the applicable account controls without a VPN. Their endpoints and any exposed management services still need separate checks.
This is increasingly common for:
- SaaS SMEs with no internal infrastructure
- Fully remote-first businesses using Zero Trust / conditional-access patterns
- Organisations that have already retired legacy LAN-dependent applications
Section 05
Where Conditional Access helps without a VPN
Microsoft Entra ID Conditional Access, Okta, and Google Workspace Context-Aware Access can enforce:
- MFA per sign-in
- Device-compliance requirement (MDM-enrolled, encrypted, patched)
- Risk-based blocks for unusual locations or impossible travel
- Phishing-resistant MFA for admin roles
Configured properly, this provides stronger authentication and authorisation than a traditional VPN with a shared password plus one-time code. It helps with identity enforcement but does not replace boundary firewall or endpoint checks.
Section 06
VPN rules that still apply to remote workers
Regardless of whether a VPN is in place:
- Organisation-issued home-office routers are in scope; ordinary privately owned home routers are outside the boundary, while work devices remain in scope.
- MFA on email and cloud services is required for everyone.
- Use stronger, phishing-resistant MFA for admin accounts where supported; check the actual scheme requirement for each service.
See Cyber Essentials for remote and hybrid workforces for the complete remote-work scope.
Section 07
Bottom line
Cyber Essentials does not require a VPN. Check the actual account, remote-administration, firewall and endpoint criteria. VPN and Conditional Access can each help, but neither architecture alone guarantees a pass.
Start Cyber Essentials from £299.99 + VAT | MFA for Cyber Essentials v3.3 | Free readiness check
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials Firewall Requirements: What Assessors Actually Check
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, what v3.3 (Danzell) actually says about home routers for remote workers, default credentials, and the cloud firewall configuration assessors expect in 2026.
Read articleTechnical Guides
Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices
Under v3.3, the BYOD question is harder than it looks. A clear walkthrough of which personal devices are in scope, the sub-set exclusion rules, and how to document both approaches.
Read articleTechnical Guides
Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.
Read article

